1   1  /  1  页   跳转

病毒Upsrv.dll的问题

病毒Upsrv.dll的问题

是window xp的系统,关机时就会跳出来对话框提示结束程序rund1132.exe,
后来在高人指导下查出是sys1 Rundll32.exe C:\WINDOWS\system32\Upsrv.dll,Run这个程序在作怪。
后我把Rundll32.exe C:\WINDOWS\system32\Upsrv.dll,Run)这一项我已经在sreng里删除,用LSPFIX也删了upfdll.dll,但是问题仍然没解决。
看到LSPFIX里还有一个rsvpsp.dll,是不是这个也要删除,才能解决问题

下面附上SREng.LOG
最后编辑2006-07-16 19:25:47
分享到:
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    (ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe)  [Microsoft Corporation]
    (MessengerPlus3)("D:\Program Files\MsgPlus.exe" /WinStart)  [Patchou]
    (sys1)(Rundll32.exe C:\WINDOWS\system32\Upsrv.dll,Run)  []
    (MSNShell)(D:\Program Files\MSNShell\Bin\MSNShell.exe autorun)  []
    (msnmsgr)("C:\Program Files\MSN Messenger\msnmsgr.exe" /background)  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    (load)()  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    (TkBellExe)("C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot)  [RealNetworks, Inc.]
    (NeroFilterCheck)(C:\WINDOWS\system32\NeroCheck.exe)  [Ahead Software Gmbh]
    (KernelFaultCheck)(%systemroot%\system32\dumprep 0 -k)  []
    (NeroCheck)(C:\WINDOWS\system32\\NeroCheck.exe)  [Ahead Software Gmbh]
    (RavTask)("C:\Program Files\rising\Rav\RavTask.exe" -system)  [Beijing Rising Technology Co., Ltd.]
    (RfwMain)("; "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup" -Startup)  []
    (MessengerPlus3)("D:\Program Files\MsgPlus.exe")  [Patchou]
    (helper.dll)(; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32)  []
    (assistse)(; "C:\PROGRA~1\3721\assistse.exe")  [yahoo]
    (HotKeysCmds)(; C:\WINDOWS\System32\hkcmd.exe)  [Intel Corporation]
    (IgfxTray)(; C:\WINDOWS\System32\igfxtray.exe)  [Intel Corporation]
    (IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32)  [Microsoft Corporation]
    (MINI_BFYY)(; C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe)  []
    (PHIME2002A)(; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName)  [Microsoft Corporation]
    (PHIME2002ASync)(; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC)  [Microsoft Corporation]
    (SoundMan)(; SOUNDMAN.EXE)  [Realtek Semiconductor Corp.]
    (StormCodec_Helper)(; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti)  []
    (WinampAgent)(; C:\Program Files\Winamp\winampa.exe)  []
    (YDTMain.exe)(; C:\PROGRA~1\YDT\YDTMain.exe)  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    (shell)(Explorer.exe)  [Microsoft Corporation]
    (Userinit)(C:\WINDOWS\system32\userinit.exe,)  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    (AppInit_DLLs)()  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    (UIHost)(logonui.exe)  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    ({D157330A-9EF3-49F8-9A67-4141AC41ADD4})()  []
    ({32CD708B-60A7-4C00-9377-D73EAA495F0F})(C:\WINDOWS\system32\RavExt.dll)  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
服务
[Macromedia Licensing Service / Macromedia Licensing Service]
  ("C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe")(N/A)
[Rising Proxy  Service / RfwProxySrv]
  (c:\program files\rising\rfw\rfwproxy.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Personal Firewall Service / RfwService]
  (c:\program files\rising\rfw\rfwsrv.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Process Communication Center / RsCCenter]
  ("C:\Program Files\rising\Rav\CCenter.exe")(Beijing Rising Technology Co., Ltd.)
[RsRavMon Service / RsRavMon]
  ("C:\Program Files\rising\Rav\Ravmond.exe")(Beijing Rising Technology Co., Ltd.)
[Sony SPTI Service / SPTISRV]
  (C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe)(Sony Corporation)
gototop
 

正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 496][\??\C:\WINDOWS\system32\csrss.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 520][\??\C:\WINDOWS\system32\winlogon.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 564][C:\WINDOWS\system32\services.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 576][C:\WINDOWS\system32\lsass.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
[PID: 724][C:\WINDOWS\system32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 768][C:\WINDOWS\system32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
[PID: 844][C:\Program Files\rising\Rav\CCenter.exe]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[PID: 864][C:\WINDOWS\System32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
[PID: 912][C:\WINDOWS\System32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
[PID: 976][C:\WINDOWS\System32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
[PID: 1044][C:\Program Files\rising\Rav\Ravmond.exe]  (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 26)
    [C:\Program Files\rising\Rav\BWList.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
    [C:\Program Files\rising\Rav\RsCommX.dll]  (rising)(18, 0, 0, 1)
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
    [C:\Program Files\rising\Rav\CfgDll.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [C:\Program Files\rising\Rav\RsLog.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 20)
    [C:\Program Files\rising\Rav\HOOKSYS.dll]  (Rising)(18, 1, 0, 9)
    [C:\Program Files\rising\Rav\Scanner.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
    [C:\Program Files\rising\Rav\libload.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
    [C:\Program Files\rising\Rav\VirusLib.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
    [C:\Program Files\rising\Rav\regmon.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
    [C:\Program Files\rising\Rav\HookWeb.dll]  (rising)(18, 0, 0, 1)
    [C:\Program Files\rising\Rav\MemMon.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
    [C:\Program Files\rising\Rav\expscan.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [C:\Program Files\rising\Rav\mPorts.dll]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 3)
    [C:\Program Files\rising\Rav\MailMon.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
    [C:\Program Files\rising\Rav\SpamEng.dll]  (N/A)(18, 0, 0, 6)
    [C:\Program Files\rising\Rav\engine.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
    [C:\Program Files\rising\Rav\PostTrt.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
    [C:\Program Files\rising\Rav\UnExe.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
    [C:\Program Files\rising\Rav\ScanExec.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
    [C:\Program Files\rising\Rav\ScanEx.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
    [C:\Program Files\rising\Rav\NvFile.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 7)
    [C:\Program Files\rising\Rav\ScanMac.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 8)
    [C:\Program Files\rising\Rav\ScanSct.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 17)
    [C:\Program Files\rising\Rav\Unpacker.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
    [C:\Program Files\rising\Rav\ExtOLE.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
    [C:\Program Files\rising\Rav\ExtMail.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 13)
[PID: 1124][c:\program files\rising\rfw\rfwsrv.exe]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 32)
    [c:\program files\rising\rfw\RfwRule.dll]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 13)
    [c:\program files\rising\rfw\rfwlog.dll]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 6)
    [c:\program files\rising\rfw\Rfwdrv.dll]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 21)
    [c:\program files\rising\rfw\MonDrv.dll]  (rs)(1, 0, 0, 4)
    [c:\program files\rising\rfw\ProcLib.dll]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 9)
[PID: 1272][C:\WINDOWS\system32\spoolsv.exe]  (Microsoft Corporation)(5.1.2600.2696 (xpsp_sp2_gdr.050610-1519))
[PID: 1368][C:\Program Files\rising\Rav\RavStub.exe]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 16)
    [C:\Program Files\rising\Rav\RsCommX.dll]  (rising)(18, 0, 0, 1)
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[PID: 1572][C:\WINDOWS\System32\svchost.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 1872][C:\WINDOWS\Explorer.EXE]  (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\RavExt.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [C:\WINDOWS\System32\igfxpph.dll]  (Intel Corporation)(3,0,0,1773)
    [C:\WINDOWS\System32\hccutils.DLL]  (Intel Corporation)(3,0,0,1773)
    [C:\WINDOWS\system32\igfxres.dll]  (Intel Corporation)(3,0,0,1773)
    [C:\WINDOWS\System32\igfxsrvc.dll]  (Intel Corporation)(3,0,0,1773)
    [C:\WINDOWS\System32\igfxdev.dll]  (Intel Corporation)(3,0,0,1773)
    [C:\PROGRA~1\3721\Assist\asnoad.dll]  ()(1, 0, 0, 9)
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  (Amaze Soft)(1, 1, 4, 0)
    [C:\WINDOWS\system32\msdmo.dll]  (N/A)(N/A)
    [c:\progra~1\3721\assist\adfilter.dll]  ( )(1, 0, 1, 6)
    [C:\PROGRA~1\3721\Assist\repair.dll]  (北京三七二一科技有限公司)(1, 0, 2, 4)
    [C:\PROGRA~1\3721\Assist\asfsks.dll]  (3721.com)(2, 1, 1, 87)
    [C:\PROGRA~1\3721\Assist\optimum.dll]  (N/A)(N/A)
    [C:\PROGRA~1\3721\Assist\assecblk.dll]  (3721)(1, 0, 0, 9)
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [C:\Program Files\3721\Assist\asbar.dll]  (3721)(1, 0, 1, 1021)
    [C:\PROGRA~1\3721\Assist\TbWrap.dll]  (3721)(1, 0, 0, 2)
    [C:\PROGRA~1\3721\Assist\aswiper.dll]  (3721)(1, 0, 1, 1004)
    [C:\PROGRA~1\3721\Assist\asiesec.dll]  (yahoo)(1, 0, 1, 1000)
    [C:\WINDOWS\system32\xunleibho_v4.dll]  ()(4, 3, 2, 29)
    [D:\PROGRA~1\KuGoo2\KUGOO3~1.OCX]  (N/A)(N/A)
gototop
 

[PID: 2020][c:\program files\rising\rfw\RfwMain.exe]  (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 51)
    [c:\program files\rising\rfw\RsGuiLib.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 23)
    [c:\program files\rising\rfw\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [c:\program files\rising\rfw\PngDll.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
[PID: 432][C:\WINDOWS\System32\alg.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 484][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  (RealNetworks, Inc.)(0.1.0.3292)
[PID: 1628][C:\Program Files\rising\Rav\RavTask.exe]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 22)
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
    [C:\Program Files\rising\Rav\CfgDll.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
    [C:\Program Files\rising\Rav\RsCommX.dll]  (rising)(18, 0, 0, 1)
[PID: 2052][D:\Program Files\MsgPlus.exe]  (Patchou)(3, 63, 0, 148)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
[PID: 2060][C:\Program Files\rising\Rav\Ravmon.exe]  (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 28)
    [C:\Program Files\rising\Rav\RsGuiLib.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 24)
    [C:\Program Files\rising\Rav\BWList.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
    [C:\Program Files\rising\Rav\CfgDll.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
    [C:\Program Files\rising\Rav\RsCommX.dll]  (rising)(18, 0, 0, 1)
    [C:\Program Files\rising\Rav\PngDll.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
[PID: 2116][C:\WINDOWS\system32\ctfmon.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 2232][C:\WINDOWS\system32\Rundll32.exe]  (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
    [C:\WINDOWS\system32\Upsrv.dll]  (N/A)(N/A)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
[PID: 2268][D:\Program Files\MSNShell\Bin\MSNShell.exe]  (N/A)(N/A)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
[PID: 192][D:\TT\TTraveler.exe]  (腾讯公司)(3.0.0.250)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [D:\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  (腾讯公司)(1, 1, 0, 5)
    [D:\TT\Plugins\TWeather\TWeather.dll]  ()(1, 0, 0, 3)
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
    [D:\TT\PersonalDesktop.dll]  (深圳市腾讯计算机系统公司QQ工作小组)(1, 0, 0, 4)
    [C:\Program Files\3721\Assist\asbar.dll]  (3721)(1, 0, 1, 1021)
    [C:\WINDOWS\system32\UNISPIM.IME]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [C:\WINDOWS\system32\upengine.dll]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
[PID: 4076][C:\Program Files\MSN Messenger\msnmsgr.exe]  (Microsoft Corporation)(7.5.0324)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [D:\Program Files\MSNShell\Bin\ShellDll02.dll]  (MSNShell Team)(4.2.25.4)
    [D:\Program Files\MSNShell\Bin\Skin\SkinPlusPlusDLL.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\MsgPlusH.dll]  (Patchou)(3, 63, 0, 148)
    [D:\Program Files\Detoured.dll]  (N/A)(N/A)
    [D:\Program Files\Resources\MsgPlusRes.dll]  (Patchou)(3, 63, 4, 0)
    [D:\Program Files\RichEdHook.dll]  (N/A)(N/A)
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
    [C:\WINDOWS\system32\msdmo.dll]  (N/A)(N/A)
    [D:\Program Files\libsndfile.dll]  (N/A)(N/A)
    [D:\Program Files\lame_enc.dll]  (N/A)(N/A)
    [C:\WINDOWS\system32\UNISPIM.IME]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [C:\WINDOWS\system32\upengine.dll]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  (Macromedia, Inc.)(8,0,24,0)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
[PID: 2632][D:\Program Files\QQ.exe]  (TENCENT)(0, 0, 0, 0)
    [D:\Program Files\QQBaseClassInDll.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQHelperDll.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\BasicCtrlDll.dll]  (Tencent)(5, 0, 200, 14)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [D:\Program Files\QQAPI.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\TIMProxy.dll]  (tencent)(0, 3, 2, 4)
    [D:\Program Files\HostingMgr.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\CameraDll.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\LoginCtrl.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\npkcntc.dll]  (INCA Internet Co., Ltd.)(2005, 9, 1, 1)
    [D:\Program Files\npkpdb.dll]  (INCA Internet Co., Ltd.)(2003, 10, 1, 1)
    [D:\Program Files\QQRes.dll]  (tencent)(1, 0, 0, 1)
    [D:\Program Files\QQMainFrame.dll]  (N/A)(N/A)
    [D:\Program Files\CQQApplication.dll]  (N/A)(N/A)
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)
    [D:\Program Files\NewSkin.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\MailSummary.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQSpace.dll]  ()(1, 0, 0, 1)
    [C:\WINDOWS\system32\msdmo.dll]  (N/A)(N/A)
    [D:\Program Files\QQGroupMng.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQSysMsgMng.dll]  (N/A)(N/A)
    [D:\Program Files\QQConfigPlugin.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\UserDefinedHead.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQAllInOne.dll]  (N/A)(N/A)
    [D:\Program Files\SCCore.dll]  (N/A)(N/A)
    [D:\Program Files\QQCustomFace.dll]  (N/A)(N/A)
    [D:\Program Files\FlashAvatarDll.dll]  ()(1, 4, 0, 1)
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  (Macromedia, Inc.)(8,0,24,0)
    [D:\Program Files\ImageOle.dll]  (TODO: (Company name))(1.0.0.1)
    [D:\Program Files\QQAvatar.dll]  (N/A)(N/A)
    [D:\Program Files\QQSceneMng.dll]  (N/A)(N/A)
    [D:\Program Files\LongConnection.dll]  (tencent)(0, 3, 3, 8)
    [D:\Program Files\QRingMng.dll]  (N/A)(N/A)
    [D:\Program Files\PhoneAPI.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\DialerAllinOne.dll]  (tencent)(1, 4, 0, 0)
    [D:\Program Files\QQPet.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQMagicFace.dll]  ()(1, 0, 0, 1)
    [C:\WINDOWS\system32\UNISPIM.IME]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [C:\WINDOWS\system32\upengine.dll]  (北京清华紫光软件股份有限公司)(3.0.0.3045)
    [D:\Program Files\BQQApplication.dll]  (N/A)(N/A)
    [D:\Program Files\QQPlugin.dll]  (N/A)(N/A)
    [D:\Program Files\PersonalDesktop.dll]  (深圳市腾讯计算机系统公司QQ工作小组)(1, 0, 0, 2)
    [D:\Program Files\QQFileTransfer.dll]  (Tencent)(5, 0, 202, 40)
    [C:\WINDOWS\system32\RavExt.dll]  (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
    [D:\Program Files\CommercesMng.dll]  ()(1, 0, 0, 1)
    [D:\Program Files\QQAddr.dll]  (深圳市腾讯计算机系统有限公司)(5, 0, 101, 141)
    [D:\Program Files\QQPhoneHelper.dll]  (腾讯科技(深圳)有限公司)(2, 0, 4, 40)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [D:\Program Files\GroupConnection.dll]  (Tencent)(5, 0, 202, 30)
[PID: 2608][D:\Program Files\TIMPlatform.exe]  (tencent)(0, 3, 1, 8)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [D:\Program Files\TIMProxy.dll]  (tencent)(0, 3, 2, 4)
[PID: 2136][C:\Program Files\WinRAR\WinRAR.exe]  (N/A)(N/A)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
[PID: 2208][C:\DOCUME~1\李婷\LOCALS~1\Temp\Rar$EX73.765\SREng2\SREng.exe]  (Smallfrogs Studio)(2.0.21.505)
    [D:\Program Files\MSNShell\Bin\ShellDll.dll]  (N/A)(N/A)
    [D:\Program Files\MsgPlusLoader1.dll]  (Patchou)(3, 63, 4, 0)
    [C:\WINDOWS\system32\upfdll.dll]  (N/A)(N/A)

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

顶上去
gototop
 

晕,有哪位高人进来解答一下吧
gototop
 

打开SRE 启动项目 注册表 删除
(sys1)(Rundll32.exe C:\WINDOWS\system32\Upsrv.dll,Run) []

重启..删除C:\WINDOWS\system32\Upsrv.dll ...LSF修复..
gototop
 

请到http://forum.ikaka.com/topic.asp?board=67&artid=5188931,下载,LSPFix.exe,WinsockXPFix这两个软件
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows

运行LSPFix.exe
删除
upfdll.dll
附说明一份
LSPFix.exe这个软件主要用来辅助修复HijackThis扫描发现的O10项。
使用时,请关闭所有IE界面和文件夹界面后运行LSPFix,运行后,把要修复的那一个O10项从左边转到右边,点“Finish”即可。(不过这之前,需要在“I know what I`m doing”前面打勾。)
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项
C:\WINDOWS\system32\Upsrv.dll

双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\WINDOWS\system32\Upsrv.dll
C:\WINDOWS\system32\upfdll.dll
修复后重启,如果无法上网,请运行WinsockXPFix,让它修复一下。
回到正常模式,请再扫日志粘上来。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT